Top News | Art | Business | Celebrities | Entertainment | Fun stuff | Health | Hobbies | Industry | Internet | IT
Life style | Music | Politics | Products | Programming | Religion and Spirituality | Science | Society | Sports
Technology | Travel | Universities | USA | Video games | World news
 

Top stories
Advertising
Blogging
Cybercrime
Digital Content
E-Business
Egovernment
E-government
EMarketing
ISP
Java
New Web Sites
Podcast
Privacy and Security
RSS / XML
Search Engines
Social Networking
Spam
Top Stories
Web Development
Web Hosting
Web Services

Privacy and security news and privacy and security widget


Monday, November 10, 2008 ( change date )


Oracle WebLogic Hit With Zero-Day Exploit
A workaround emerged from Oracle as news circulated of a remotely exploitable flaw, without requiring authentication, involving the WebLogic platform.Both the WebLogic Server and WebLogic Express products, acquired by Oracle when the company purchased BEA, suffer from the newly disclosed vulnerability. SANS internet Storm Center said the problem stems from the Apache Connector used by the products. A WebLogic advisory noted the flaw could be exploited without authentication. Sites using Apache servers that are already configured with the mod_security module are protected from this vulnerability by the default core ruleset, according to the advisory. Using mod_security with the WebLogic plug-in for Apache serves as one workaround suggested by Oracle. The other workaround calls for an edit to httpd.conf and a restart: It is possible to configure Apache and avert this vulnerability by rejecting certain invalid requests. To do so, add the following parameter to the httpd.conf file and
feedburner.com Monday, November 10, 2008

Metasploit's Moore Sapped Via DNS Flaw
The same critical DNS issue that HD Moore and his associates raced to include in their security testing toolkit, the Metasploit Project, bounced back against the noteworthy security researcher.Security pros and other techies who see the boundary-pushing actions of Moore and Metasploit as more of a hindrance than a help to security may have enjoyed the schadenfreude surrounding Moore today. Moore detailed what happened on a blog post at Metasploit. The incident hit an AT&T DNS cache server; the affected machine coincidentally served "as an upstream forwarder for an internal DNS machine at BreakingPoint Systems," which is Moore's company. "This attack affected anyone in the Austin, Texas region using that AT&T internet Services (previously SBC) DNS server. The attack itself was not malicious, did not load malware, and from an operational standpoint, had zero impact," said Moore. Employees at his company noticed problems when the cache-poisoned DNS machine at AT&T returned a 404 error
feedburner.com Monday, November 10, 2008

CREATE YOUR NEWS WIDGET

Free RSS News Feeds, News Widget - Choose A Topic On Your News Widget CHOOSE THE TOPIC ON YOUR NEWS WIDGET


Search by keywords...


RSS widgets for your website - Customize your RSS Widget CHOOSE THE METHOD OF INSTALLATION

Blogger

Typepad

Facebook

MySpace

Wordpress

Flash
More methods...

Advanced Widget Customization Options - Customize Your News Widget CUSTOMIZE YOUR NEWS WIDGET

Number of news stories
Show the summaries?
Advanced customization options


Installation Methods Of Widget At Feedzilla - Install Your Widget INSTALL YOUR WIDGET


Archived privacy and security news stories.

Available news archives.

January 2009
S M T W T F S
         1    2    3  
 4    5    6    7    8    9    10  
 11    12    13    14    15    16    17  
 18    19    20    21    22    23    24  
 25    26    27    28    29    30    31  
             
December 2008
S M T W T F S
   1    2    3    4    5    6  
 7    8    9    10    11    12    13  
 14    15    16    17    18    19    20  
 21    22    23    24    25    26    27  
 28    29    30    31        
             
November 2008
S M T W T F S
             1  
 2    3    4    5    6    7    8  
 9    10    11    12    13    14    15  
 16    17    18    19    20    21    22  
 23    24    25    26    27    28    29  
 30              
October 2008
S M T W T F S
       1    2    3    4  
 5    6    7    8    9    10    11  
 12    13    14    15    16    17    18  
 19    20    21    22    23    24    25  
 26    27    28    29    30    31    
             
September 2008
S M T W T F S
   1    2    3    4    5    6  
 7    8    9    10    11    12    13  
 14    15    16    17    18    19    20  
 21    22    23    24    25    26    27  
 28    29    30          
             
August 2008
S M T W T F S
           1    2  
 3    4    5    6    7    8    9  
 10    11    12    13    14    15    16  
 17    18    19    20    21    22    23  
 24    25    26    27    28    29    30  
 31              
July 2008
S M T W T F S
     1    2    3    4    5  
 6    7    8    9    10    11    12  
 13    14    15    16    17    18    19  
 20    21    22